← All CVEs

CVE-2020-15778

high · 7.4

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

7.4
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2020-07-24
Published

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
openbsdopenssh< 8.3
openbsdopenssh8.3
openbsdopenssh8.3
netappa700s_firmwareall versions
netappa700sall versions
netappactive_iq_unified_manager>= 9.5
netapphci_management_nodeall versions
netappsolidfireall versions
netappsteelstore_cloud_integrated_storageall versions
netapphci_compute_nodeall versions
netapphci_storage_nodeall versions
broadcomfabric_operating_systemall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-15778